IP Library Granted Patent US 10,992,715
Granted Patent B2
US 10,992,715 · App. 16/445,431 · Granted Apr 27, 2021

System and method for application software security and auditing

Inventors: Michael Feiertag (San Francisco, CA); Garrett Held (San Francisco, CA); Andre Eriksson (San Francisco, CA); William Saar (San Francisco, CA)
Assignee: Rapid7, Inc.
H04L63/20G06F8/61G06F21/577G06F21/6245H04L63/1425G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,992,715
App. No.
16/445,431
Granted
Apr 27, 2021
Kind
B2
Abstract

A system and method for application software security and auditing are disclosed. A particular embodiment includes an application security management system configured to: instrument one or more data input and output points of an application for one or more instances of data identified as sensitive data, access one or more policies corresponding to the one or more instances of the sensitive data, trace the one or more instances of the sensitive data through the application in association with the one or more policies, and generate an audit of each instance of the sensitive data indicating a route from which the sensitive data is accessed, to where the sensitive data is written, and where the sensitive data surfaces in the application.

Claims (44)

1. A system comprising:

a data processor;

a network interface, in data communication with the data processor, for communication on a data network; and

an application security management system, executable by the data processor, to: instrument one or more data input and output points of an application for one or more instances of data designated as sensitive data,

access one or more policies corresponding to the one or more instances of the sensitive data,

trace the one or more instances of the sensitive data through the application in association with the one or more policies each defined by a set of log rules, and

generate an audit of each instance of the sensitive data and each instance of the set of log rules used by the each instance of the sensitive data,

wherein the audit indicates a route leading to a log from which the sensitive data is accessed,

wherein in addition to being defined by the set of log rules, the one or more policies comprise at least a count policy, an alert policy, a redaction policy, and an encryption policy each defined by a set of user output rules,

wherein for each read, modification, or access of each instance of the sensitive data in the log based on the set of log rules, the count policy generates a counter for the each instance, the alert policy generates an alert for the each instance, the redaction policy obscures the each instance from being used, and the encryption policy encrypts the each instance to render the each instance unusable.

2. The system of claim 1 , further comprising:

installing a plurality of input/output (I/O) instrumentation components that correspond to one or more I/O operations at the one or more data input and output points.

3. The system of claim 1 , further comprising:

collecting trace data that corresponds to one or more data elements accessed by the application and previously designated as the sensitive data.

4. The system of claim 3 , further comprising:

identifying the one or more policies corresponding to the one or more instances of the sensitive data by causing transfer of information indicative of the trace data to a host site.

5. A computer-implemented method comprising:

instrumenting one or more data input and output points of an application for one or more instances of data designated as sensitive data;

accessing one or more policies corresponding to the one or more instances of the sensitive data;

tracing the one or more instances of the sensitive data through the application in association with the one or more policies each defined by a set of log rules; and

generating an audit of each instance of the sensitive data and each instance of the set of log rules used by the each instance of the sensitive data,

wherein the audit indicates a route leading to a log from which the sensitive data is accessed;

wherein in addition to being defined by the set of log rules, the one or more policies comprise at least a count policy, an alert policy, a redaction policy, and an encryption policy each defined by a set of user output rules,

wherein for each read, modification, or access of each instance of the sensitive data in the log based on the set of log rules, the count policy generates a counter for the each instance, the alert policy generates an alert for the each instance, the redaction policy obscures the each instance from being used, and the encryption policy encrypts the each instance to render the each instance unusable.

6. The computer-implemented method of claim 5 , further comprising:

installing a plurality of input/output (I/O) instrumentation components that correspond to one or more I/O operations at the one or more data input and output points.

7. The computer-implemented method of claim 5 , further comprising:

collecting trace data that corresponds to one or more data elements accessed by the application and previously designated as the sensitive data.

8. The computer-implemented method of claim 7 , further comprising:

identifying the one or more policies corresponding to the one or more instances of the sensitive data by causing transfer of information indicative of the trace data to a host site.

9. A non-transitory machine-useable storage medium embodying instructions which, when executed by a machine, cause the machine to:

instrument one or more data input and output points of an application for one or more instances of data designated as sensitive data;

access one or more policies corresponding to the one or more instances of the sensitive data;

trace the one or more instances of the sensitive data through the application in association with the one or more policies each defined by a set of log rules; and

generate an audit of each instance of the sensitive data and each instance of the set of log rules used by the each instance of the sensitive data,

wherein the audit indicates a route leading to a log from which the sensitive data is accessed,

wherein in addition to being defined by the set of log rules, the one or more policies comprise at least a count policy, an alert policy, a redaction policy, and an encryption policy each defined by a set of user output rules,

wherein for each read, modification, or access of each instance of the sensitive data in the log based on the set of log rules, the count policy generates a counter for the each instance, the alert policy generates an alert for the each instance, the redaction policy obscures the each instance from being used, and the encryption policy encrypts the each instance to render the each instance unusable.

10. The non-transitory machine-useable storage medium of claim 9 , further comprising:

installing a plurality of input/output (I/O) instrumentation components that correspond to one or more I/O operations at the one or more data input and output points.

11. The non-transitory machine-useable storage medium of claim 9 , further comprising:

collecting trace data that corresponds to one or more data elements accessed by the application and previously designated as the sensitive data.

12. The non-transitory machine-useable storage medium of claim 11 , further comprising:

identifying the one or more policies corresponding to the one or more instances of the sensitive data by causing transfer of information indicative of the trace data to a host site.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2019
From: FEIERTAG, MICHAEL; ERIKSSON, ANDRE; HELD, GARRETT; SAAR, WILLIAM
To: RAPID7, INC.
Reel/Frame 049516/0596 →
Continuity (2)
Continuation 15480229 · Apr 5, 2017
Related Publication 20190306198A1 · Oct 3, 2019